MailGuard 18 June 2025 14:01:53 AEST 6 MIN READ

Don’t Press Play On This Spotify-Themed Phishing Scam

Be careful not to click on the latest phishing campaign that impersonates Spotify Support in an attempt to steal user login credentials and financial data. Designed to appear legitimate at every stage, this attack mimics Spotify’s interface, with multiple fake verification steps designed to lull users into a false sense of security.

What the scam looks like

The email, sent from the display name “Spotify-Support” using the address `julieth(dot)nziku(at)posta(dot)co(dot)tz`, is titled “Billing Issue Detected”. It warns recipients of a problem with their billing information and prompts them to click a prominent “Update Payment Info” button to avoid disruption of service.

Here's what the email looks like 👇

Spotify - 0625 - email

 

Once the user clicks the link, they are taken to a replica Spotify website hosted at `srv88702(dot)seohost(dot)com(dot)pl`, which convincingly mirrors the layout and branding of the real Spotify platform.

A step-by-step breakdown of the attack

1. Phishing Email

The message uses urgent language and a professional layout to increase trust.

Spotify - 0625 - email
2. Login Page

Users are first prompted to enter their Spotify credentials, mimicking the platform’s standard login interface.


Spotify - 0625 - login
3. Credit Card Harvesting Page

Next, users are asked to verify their billing details by entering full credit card information, including name, number, expiration date, and CVV.

Spotify - 0625 - credit card info
4. SMS Code Verification Page

A final page requests an SMS code, claiming it is required for verification. This may be used to confirm or attempt a fraudulent charge.
Spotify - 0625 - SMS verification
5. Confirmation Page and Redirect

Finally, users are shown a success message before being redirected to the legitimate Spotify site.

Spotify - 0625 - Success

This layered approach is intended to deflect suspicion by mimicking standard security checks and payment flows users have seen before.

Technical insights

The campaign combines simple HTML with a clear objective, to harvest multiple forms of personal information. The first two pages (login and payment verification) do not immediately arouse suspicion due to their visual fidelity. The third step, requesting an SMS code, is likely to catch many users off guard, especially if a real-time transaction verification is involved.

Redirecting users to the legitimate Spotify website is a common technique used to conceal the fraud and delay detection or reporting.

Threat Type: Phishing (credential harvesting)

Sender Display Name: Spotify-Support

Sending Email Address:  `julieth(dot)nziku(at)posta(dot)co(dot)tz` 

Target: Login credentials, credit card data, and SMS codes

Stay Safe - Know the Signs

MailGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.

Avoid emails that:

  • Aren’t addressed to you personally.
  • Are unexpected and urge immediate action.
  • Contain poor grammar or miss crucial identifying details.
  • Direct you to a suspicious URL that isn’t associated with the genuine company.

Many businesses turn to MailGuard after a near miss or incident. Don't wait until it's too late. Reach out to our team for a confidential discussion by emailing expert@mailguard.com.au or calling 1300 30 44 30.

One Email Is All That It Takes   

All that it takes to devastate your business is a cleverly worded email message that can steal sensitive user credentials or disrupt your business operations. If scammers can trick one person in your company into clicking on a malicious link or attachment, they can gain access to your data or inflict damage on your business.     

For a few dollars per staff member per month, you can protect your business with MailGuard's specialist, 'zero zero-day' email security. Special Ops for when speed matters!  Our real-time 'zero zero-day', email threat detection amplifies our client’s intelligence, knowledge, security and defence. Talk to a solution consultant at MailGuard today about securing your company's inboxes.  

Stay up-to-date with MailGuard's latest blog posts by subscribing to free updates. Subscribe to weekly updates by clicking on the button below.  

Keep Informed with Weekly Updates